/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Actually, I'm running kernel 2.0.36 and ipfwadm. Here's my socks5.conf
file:
auth 10.0.4. - n
auth 10.0.5. - n
permit - - 10.0.4. - - -
permit - - 10.0.5. - - -
deny - - - - - -
I got this from the list archives, and socks seems to work right...sort
of.
Here's my ifconfig:
lo Link encap:Local Loopback
inet addr:127.0.0.1 Bcast:127.255.255.255 Mask:255.0.0.0
UP BROADCAST LOOPBACK RUNNING MTU:3584 Metric:1
RX packets:1106 errors:0 dropped:0 overruns:0 frame:0
TX packets:1106 errors:0 dropped:0 overruns:0 carrier:0
collisions:0
eth0 Link encap:Ethernet HWaddr 00:A0:24:CE:F1:90
inet addr:192.168.0.3 Bcast:192.168.0.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:613991 errors:0 dropped:0 overruns:0 frame:0
TX packets:229797 errors:0 dropped:0 overruns:0 carrier:0
collisions:22322
Interrupt:12 Base address:0xe400
eth0:1 Link encap:Ethernet HWaddr 00:A0:24:CE:F1:90
inet addr:192.168.0.32 Mask:255.255.255.0
UP RUNNING MTU:1500 Metric:1
RX packets:1 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0
eth0:2 Link encap:Ethernet HWaddr 00:A0:24:CE:F1:90
inet addr:192.168.0.34 Mask:255.255.255.0
UP RUNNING MTU:1500 Metric:1
RX packets:2 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0
eth1 Link encap:Ethernet HWaddr 00:E0:29:3D:9C:7B
inet addr:10.0.4.1 Bcast:10.0.4.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:148024 errors:0 dropped:0 overruns:0 frame:0
TX packets:21942 errors:0 dropped:0 overruns:0 carrier:0
collisions:2
Interrupt:10 Base address:0xdc00
eth2 Link encap:Ethernet HWaddr 00:E0:29:3D:A0:E5
inet addr:10.0.5.1 Bcast:10.0.5.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:8921 errors:0 dropped:0 overruns:0 frame:0
TX packets:11073 errors:0 dropped:0 overruns:0 carrier:0
collisions:5
Interrupt:9 Base address:0xe000
eth1 and eth2 are networks being masq'ed. The external IP address should
be 192.168.0.3 (eth0), but for some reason it's using 192.168.0.34
(eth0:2). If I take eth0:2 down, then it starts using 192.168.0.32
(eth0:1). And of course if I add an eth0:3, it starts using that one. It
seems to want to use whatever IP was set up last on eth0, even if it's a
virtual IP.
I think that this is a socks5 issue. I tried using FTP from a machine
behind the masq server, and connected to my FTP server outside the masq
server. The log entry says that it came from 192.168.0.3 (eth0), so it
looks like masq is using the right Interface. It's just ICQ connects
going through socks5 that seem to be using eth0:2.
Any ideas?
Craig
On Tue, 18 Jan 2000, Gregory Leblanc wrote:
> Craig Baird wrote:
> >
> > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> >
> > We are using IP-masq to deliver Internet connectivity to one of our
> > customers via a DSL line. This customer relies heavily on ICQ, so as a
> > result, I have NEC's socks5 daemon running on the masq server. However,
> > after I got socks5 up and running, I started getting the following error
> > in my syslog (IP's changed to protect the innocent) each time I tried to
> > send an ICQ message from the masqed network, through the firewall to one
> > of the machines on my LAN:
> >
> > Jan 18 08:57:03 hostname kernel: IP fw-out rej eth0 TCP 192.168.0.34:27256
> > 192.168.0.15:23964 L=44 S=0x00 I=40065 F=0x0000 T=64
> >
> > 192.168.0.15 is the machine that I sent the ICQ message to. However,
> > 192.168.0.34 is actually an IP alias on eth0 for a virutal webhost. (it's
> > eth0:2, to be precise). My eth0 interface is actually 192.168.0.3. It's
> > for this reason that it was being rejected. I had rules set up to allow
> > outgoing traffic on 192.168.0.3 (eth0), but I didn't have rules set up to
> > allow outgoing traffic on 192.168.0.34 except port 80. Allowing all
> > outbound traffic from 192.168.0.34 has fixed the problem, but I can't
> > understand why it was using the address for eth0:2 instead of eth0.
> > Incidentally, it seems to use whichever IP address was last configured on
> > eth0. If I add an eth0:3, it uses that IP. Anyway, this sort of bugs me.
> > I'm able to work around it by adding this address to rc.firewall, but
> > isn't there any way to force it to use the IP for just plain old eth0? I
> > don't know if this is related to IP-masq or socks5, but I thought I'd
> > throw it out there to see if anyone has seen this before.
>
> This sounds suspiciously similar to the problem that Doug Apel was
> having before the end of the year. I'm curious as to whether you're
> running 2.2.14, or an earlier kernel. (my personal guess is that it's
> 2.2.14...). Let us know which kernel, and we'll see what we can come up
> with,
> Greg
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.